What this is
What is an anti-bribery risk assessment?
What is an anti-bribery risk assessment?
A structured assessment of where an organisation is exposed to bribery and corruption, by geography, sector, transaction type, business model and third party relationship, and what controls address each exposure. It informs the design of the whole programme, and under UK law it is the element on which the statutory defence rests.
Why does the assessment matter so much legally?
Because the UK failure to prevent offences provide a defence only where procedures were adequate or reasonable, and both standards are judged as proportionate to risk. Proportionality cannot be demonstrated without an assessment establishing what the risk was. Home Office guidance on the fraud offence states directly that a thorough risk assessment is the foundation and that all other principles should be informed by it.
Scope
When is an anti-bribery risk assessment required?
The assessment establishes exposure and calibrates the programme. It is not the programme, and it is not the due diligence performed on individual counterparties.
Use this template when
- Establishing the organisation-wide exposure by geography, sector, transaction type and business model
- Assessing third party exposure: agents, distributors, consultants, customs brokers and joint venture partners
- Reviewing after entering a new market, acquiring a business, or changing the intermediary model
- Calibrating due diligence depth, approval thresholds and monitoring intensity to the assessed risk
- Evidencing proportionality for the statutory defences under UK failure to prevent offences
Do not use it for
- Individual counterparty due diligence, which applies the assessment's conclusions to a specific third party
- The code of conduct and gifts and hospitality policy, which are controls the assessment informs
- Whistleblowing arrangements, which are a separate mechanism with their own requirements
- Payment and procurement fraud controls, which address a different offence with overlapping controls
- Sanctions and export control screening, which is a distinct regime with strict liability characteristics
Compliance mapping
Which ISO 37001 cl.4.5 requirements does this satisfy?
Anti-bribery obligations combine a management system standard with criminal offences whose defences turn on the quality of the risk assessment.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 37001 cl.4.5 | Bribery risk assessment identifying, analysing, evaluating and prioritising bribery risk, reviewed regularly | Exposure |
| Bribery Act 2010 s.7 | Corporate offence of failure to prevent bribery, with adequate procedures as the defence | Header |
| Bribery Act guidance, principle 3 | Risk assessment as one of six principles underpinning adequate procedures | Exposure |
| Criminal Finances Act 2017 ss.45-46 | Failure to prevent facilitation of UK and foreign tax evasion, with reasonable procedures as the defence | Header |
| ECCTA 2023, failure to prevent fraud | In force 1 September 2025 for large organisations, with reasonable procedures as the only defence | Header |
| FCPA anti-bribery and accounting provisions | Prohibition on corrupt payments to foreign officials, plus books and records and internal controls | Controls |
| ISO 37001 cl.8.2 | Due diligence on transactions, projects, business associates and personnel proportionate to assessed risk | Controls |
| ISO 37001 cl.9.2 | Internal audit of the anti-bribery management system at planned intervals | Assurance |
What it does not cover
- Counterparty due diligence, which applies the assessment to a specific third party before engagement.
- Gifts, hospitality and facilitation payment policy, which are controls calibrated by the assessment.
- Whistleblowing arrangements, which operate independently and have their own protections and timescales.
- Sanctions and export control screening, a separate regime with different liability characteristics.
- The books and records controls required under the FCPA accounting provisions, which sit with finance.
How to complete it
How to complete an anti-bribery risk assessment, step by step
An assessment that supports a legal defence has to show its working. Four things determine whether it does.
Identify the specific interactions where bribery is plausible: permits, licences, inspections, customs clearance, tender processes, tax settlements and anything mediated by an agent paid on outcome. Then establish who performs them, through whom, and with what oversight. A country risk score tells you the weather; this tells you where the exposure sits.
All three UK offences turn on acts by associated persons: employees, agents, subsidiaries, and anyone performing services for or on behalf of the organisation. The assessment has to reach them, and the guidance is clear that smaller organisations may find themselves subject to requirements flowed down contractually because they are associated persons of someone larger.
The Home Office guidance states that organisations should not duplicate existing work, and equally that existing regulatory compliance mechanisms do not automatically amount to reasonable procedures. The correct approach is to map what exists against the risks this assessment identified and to record where the gaps are, rather than asserting that a regulated business is therefore compliant.
The defence is judged on procedures in place at the time of the offence. An assessment dated four years ago, covering a business that has since entered two markets and acquired a distributor, does not support proportionality for the current operation. Review annually and on any material change to markets, model or intermediaries.
What auditors find
Most common anti-bribery risk assessment findings
Findings here concern whether the assessment could actually support a defence.
| Finding | Clause | What fixes it |
|---|---|---|
| Assessment based on country risk indices with no transaction-level analysis. | ISO 37001 cl.4.5 | Identify the specific transactions and intermediaries where exposure arises. |
| Third parties and associated persons not covered. | Bribery Act s.7 | All three UK offences turn on associated persons; the assessment must reach them. |
| Existing regulatory compliance cited as evidence of reasonable procedures. | ECCTA guidance | Map existing controls against identified risks and record gaps; regulation is not a defence. |
| Assessment not reviewed after entering a new market or acquiring a business. | ISO 37001 cl.4.5 | Review on change; the defence is judged on procedures at the time of the offence. |
| Due diligence depth uniform rather than calibrated to assessed risk. | ISO 37001 cl.8.2 | Tier due diligence; uniform depth over-burdens low risk and under-examines high risk. |
| Fraud risk not assessed despite the September 2025 offence. | ECCTA | Extend the assessment to fraud committed for the organisation's benefit; it is a separate offence. |
| No top level commitment evidenced beyond a signed policy. | Bribery Act guidance, principle 1 | Evidence engagement: resourcing decisions, escalations handled, communication from leadership. |
| Training generic rather than targeted at the assessed high-risk roles. | ISO 37001 cl.7.3 | Target training at people performing the transactions the assessment identified. |
| Monitoring and review principle unaddressed. | Bribery Act guidance, principle 6 | Define what is monitored, how often, and what happens when something is found. |
| Assessment undated or unowned. | ISO 37001 cl.4.5 | Date, sign and own it; an undated assessment cannot evidence procedures at a point in time. |
Case in point
Case in point: the third offence nobody assessed for
The UK now has three failure to prevent offences. Bribery came first under the Bribery Act 2010, with adequate procedures as the defence. Facilitation of tax evasion followed under the Criminal Finances Act 2017, with reasonable procedures. The failure to prevent fraud offence under ECCTA came into force on 1 September 2025, applying to large organisations across all sectors, carrying an unlimited fine, with reasonable procedures as the only defence.
The Home Office guidance published in November 2024 was described by practitioners as remarkably prescriptive relative to its predecessors, and it states plainly that a thorough risk assessment is the foundation and that the other five principles should be informed by its results. The Serious Fraud Office signalled its intention to pursue the offence from the outset.
Many organisations arrived at September 2025 with a bribery risk assessment reviewed reasonably recently and no assessment at all of where fraud might be committed for the organisation's benefit. Those are overlapping but distinct exposures, and only one of them had been mapped.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
6 sections
- Reference
- CMP-043
- Archetype
- Assessment
- Record ID
- ABR-2026-000
- Scoring
- Residual band
- Direction
- Low is good
- Singleton
- Yes
- Basis
- ISO 37001 cl.4.5
- Links
- Links Conflict of interest, Procurement
- Tags
- Ethics, Bribery
- Sections
- 6
- Fields
- 45
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 4
Header
10 fieldsAssessment ID*
Auto sequence. Format ABR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Scope Assessed*
Assessed By*
Third Party Advice Taken*
- Yes3 pts
- No1 pt
Facilitation Payments Are Still Illegal At Home
A small payment to speed up an inspection or a permit is normal practice in some markets and a criminal offence in the jurisdiction your company reports into.
Exposure
6 fieldsProcurement Decisions Exposed*
- Yes3 pts
- Partly1 pt
- No0 pts
Permit And Inspection Interactions Exposed*
- Yes3 pts
- Partly1 pt
- No0 pts
Customer Relationships Exposed*
- Yes3 pts
- Partly1 pt
- No0 pts
Agents Or Intermediaries Used*
- Yes3 pts
- Partly1 pt
- No0 pts
High Risk Jurisdictions Involved*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Charitable Or Political Donations Made*
- Yes3 pts
- Partly1 pt
- No0 pts
Controls
6 fieldsPolicy In Place And Communicated*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Gifts And Hospitality Register Maintained*
- Yes3 pts
- Partly1 pt
- No0 pts
Approval Thresholds Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Third Party Due Diligence Performed*
- Yes3 pts
- Partly1 pt
- No0 pts
Contract Clauses Included*
- Yes3 pts
- Partly1 pt
- No0 pts
Facilitation Payments Prohibited Explicitly*
- Yes3 pts
- Partly1 pt
- No0 pts
Assurance
6 fieldsTraining Delivered To Exposed Roles*
- Yes3 pts
- Partly1 pt
- No0 pts
Reporting Route Available*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Expenses Reviewed For Red Flags*
- Yes3 pts
- Partly1 pt
- No0 pts
Audit Coverage Includes This*
- Yes3 pts
- Partly1 pt
- No0 pts
Concerns Raised And Handled*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Senior Commitment Demonstrated*
- Yes3 pts
- Partly1 pt
- No0 pts
Related records
1 fieldModern Slavery Assessment ID
The related labour standards assessment.
Links to CMP-042 Assessment ID
Outcome
16 fieldsResidual Band*
- Low, 1 to 45 pts
- Medium, 5 to 94 pts
- High, 10 to 142 pts
- Very high, 15 to 191 pt
- Extreme, 20 to 250 pts
Gaps Identified*
Controls Proportionate*
- Yes3 pts
- Partly1 pt
- No0 pts
Action Plan Created*
- Yes3 pts
- Not needed3 pts
- No0 pts
Feeds Management Review*
- Yes3 pts
- Partly1 pt
- No0 pts
Next Assessment Due*
Risk Assessment
Risk ID
Format RSK-2026-00000.
Links to FDN-012 Risk ID
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-043 · record IDs look like ABR-2026-000 · Links Conflict of interest, Procurement
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The assessment is the foundation of three defences. What fails is the transaction detail nobody mapped and the review that lapsed after an acquisition.
Holds the assessment against markets, transaction types and third parties, and triggers review on acquisitions, new markets and intermediary changes.

Maps existing controls against assessed risks and surfaces the gaps, rather than allowing existing compliance to be asserted as coverage.
Extends assessment and due diligence to associated persons, including agents and intermediaries who are not suppliers in the usual sense.
Targets training at the roles performing the transactions the assessment identified, rather than delivering the same module to everyone.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Anti-Bribery Risk Assessment definitions and key terms
- Associated person
- Anyone performing services for or on behalf of the organisation: employees, agents, subsidiaries, contractors and intermediaries.
- Adequate procedures
- The Bribery Act 2010 section 7 defence standard, judged against six principles and proportionate to risk.
- Reasonable procedures
- The defence standard under the tax evasion and fraud offences. The Home Office has indicated it is no more onerous than adequate.
- Facilitation payment
- A small payment to secure or expedite a routine government action. Illegal under the Bribery Act; a narrow FCPA exception exists.
- Six principles
- Top level commitment, risk assessment, proportionate risk-based procedures, due diligence, communication including training, and monitoring and review.
- Failure to prevent offence
- A corporate offence turning on an associated person's act, without requiring proof of management knowledge or intent.
- Red flag
- An indicator warranting enhanced scrutiny: unusual commission, request for payment to a third country, political connection, refusal of contract terms.
- Books and records provisions
- FCPA accounting requirements for accurate records and adequate internal accounting controls, enforced independently of bribery itself.
FAQ
Frequently asked questions about anti-bribery risk assessment
Why is the risk assessment the foundation of the defence?+
Because the defences require procedures that are adequate or reasonable, and both are judged as proportionate to the risk faced. Proportionality is unarguable without an assessment establishing what the risk was. Home Office guidance on the fraud offence states directly that a thorough risk assessment is the foundation and that the other principles should be informed by its results.
What changed on 1 September 2025?+
The failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023 came into force in England and Wales. It applies to large organisations across all sectors, makes them criminally liable where an associated person commits fraud intending to benefit the organisation, carries an unlimited fine, and provides reasonable fraud prevention procedures as the only defence. It requires no proof of management involvement.
Do our existing compliance procedures count?+
They are a starting point, not a defence. The guidance advises against duplicating existing work while making clear that existing regulatory compliance mechanisms do not automatically amount to reasonable procedures. The correct approach is to map what you have against the risks identified in this assessment and record where the gaps are.
Are small organisations affected?+
Directly, only where they meet the large organisation threshold. Indirectly, substantially: a smaller business may be an associated person of a large organisation and find fraud prevention requirements flowed down contractually. The practical effect is that the obligation propagates through supply chains well beyond the entities in scope.
How often should the assessment be reviewed?+
Annually as a minimum, and on any material change: entering a new market, acquiring a business, changing the intermediary model, or a significant change in the regulatory environment. The defence is judged on the procedures in place at the time of the offence, so an assessment describing a business you no longer are supports nothing.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Ethics, Labour and Anti-Bribery
Code of Conduct Acknowledgement
Records that a worker has read and accepted the code of conduct, at hire and on revision
Whistleblowing Report Record
Records a concern raised confidentially about wrongdoing, and how it was handled
Conflict of Interest Declaration
Records a declared interest that could affect a business decision, and how it will be managed
Modern Slavery and Labour Standards Assessment
Assesses the site and its labour supply chain for forced labour, debt bondage, withheld documents and unlawful deductions
Agency Labour Provider Assessment
Assesses an agency for how it screens, trains, inducts and supervises the people it sends
Just Culture Determination
Separates a system problem from a genuine choice to take a risk, using a consistent set of questions
More in Ethics and Conduct
Code of Conduct Acknowledgement
Records that a worker has read and accepted the code of conduct, at hire and on revision
Whistleblowing Report Record
Records a concern raised confidentially about wrongdoing, and how it was handled
Conflict of Interest Declaration
Records a declared interest that could affect a business decision, and how it will be managed
Modern Slavery and Labour Standards Assessment
Assesses the site and its labour supply chain for forced labour, debt bondage, withheld documents and unlawful deductions
Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 37001:2016 anti-bribery management systems, clauses 4.5, 8.2 and 9.2
- Bribery Act 2010 section 7 and Ministry of Justice guidance on adequate procedures
- Economic Crime and Corporate Transparency Act 2023, failure to prevent fraud, in force 1 September 2025
- Home Office guidance on failure to prevent fraud reasonable procedures, November 2024
- Criminal Finances Act 2017 sections 45 and 46, failure to prevent facilitation of tax evasion
- US Foreign Corrupt Practices Act, anti-bribery and accounting provisions
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.